unexpected MDQ calls & warnings

Andrew Jason Morgan morgan at oregonstate.edu
Mon Feb 8 23:26:06 UTC 2021


It is fairly easy to avoid CAS attribute groups when using metadata-driven configuration for CAS services.  I've been playing with that a test instance of our IDP.  However, I don't know a good way, besides these groups, to manage bundles of attributes via cas-protocol.xml.  There are some CAS Service URL patterns that I don't know how to represent in metadata files, such as "http(s)://*.oregonstate.edu".  With a wildcard like that, there isn't a static "entityID" to configure attribute release against.

If I have misunderstood anything, please let me know!

Thanks,
Andy


________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Monday, February 8, 2021 2:27 PM
To: Shib Users <Users at shibboleth.net>
Subject: Re: unexpected MDQ calls & warnings

[This email originated from outside of OSU. Use caution with links and attachments.]

https://issues.shibboleth.net/jira/browse/IDP-1723

There's no official workaround until 4.1 to prevent it, other than "don't use groups", since that's been the advice for a while.

-- Scott


--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210208/73242646/attachment.htm>


More information about the users mailing list